Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Hey CheckMates

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

To ensure continued protection, we strongly recommend installing the latest Jumbo Hotfix for your deployed version as soon as it becomes available.

Please note that customers using Check Point Live Patch will be automatically protected as the rollout begins on September 9, 2026. If you are not using Check Point Live Patch, read sk185114 for more details on how you can benefit and stay protected.

For detailed information, affected products, mitigation guidance, and remediation instructions, please refer to the following Security Advisories:
  • CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN - sk1000117
  • CVE-2026-85103: ASN.1 Decoding Heap Overflow Leading to Remote Code Execution - sk1000118
47 Replies
Pavol-T
Newcomer

Regarding CVE-2026-85103, to me it's not clear if gateways with VPN software blade disabled are affected too. Any ideas or further information? Thank you

0 Kudos
_Val_
Admin
Admin

This specific issue is about certificate processing, so it theoretically can be triggered in an environment even without VPN, but with VPN certificates.

This is what the CVE description saysA heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

0 Kudos
J_admin12
Contributor

Thanks,

At what time will the Spark SK articles be updated to show the new builds? Currently neither are showing the latest patched versions.

0 Kudos
StackCap43382
Collaborator
Collaborator

When is the CPLP package going to be pushed?

All the devices I've checked still have V18.

Will this package require any manual intervention for CPLP to apply the code fix to the processes?

 

CCSME, CCTE, CCME, CCVS
(1)
StackCap43382
Collaborator
Collaborator

Also why is the Jumbo for these CVEs integrated with dozens of other fixes? This should be a targeted JHF so people can install without a repeat of the recent DHCP bug. 

CCSME, CCTE, CCME, CCVS
0 Kudos
CaseyB
Advisor

You can manually apply the CPLP to stay on your current JHF or wait for Check Point to push it to your gateways IF you have it enabled.

0 Kudos
_Val_
Admin
Admin

Answering both questions:

1. The fixes are available immediately with LivePatch packages and can be downloaded from the SKs mentioned above or automatically through the LivePatch mechanism.
2. They are also included with JHF packages in the SKs. 

You can use either way to patch.

0 Kudos
travelmaniac
Explorer

My whole environment is still on "Urgent Take 18"...
So either something is not working in my environment, or it is a very slow staged rollout.

0 Kudos
PhoneBoy
Admin
Admin

I assume this is done on a rollout basis and not done to everyone all at ones.
If you need to apply immediately, you can download the relevant update (Take 24) from: https://support.checkpoint.com/results/sk/sk185114 

0 Kudos
StackCap43382
Collaborator
Collaborator

Done that in a lab.

Waiting to see if it actually armes the ready processes or not.

 

 

[Expert@FWA-01:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-07-15 08:13:55 sk185033
vpn1:vpnd ready livepatch 0/0 2026-07-15 08:13:55 sk185033

One row per <name>:<proc> deployment (revert/status target). Use `cplp status --patch-id <name>` for live per-pid state.
[Expert@FWA-01:0]# autoupdatercli install /home/admin/urgent_security_updates_R81_20_Bundle_T24_AutoUpdate.tar

Install request of component urgent_security_updates version 24 handled. To see installation status, see logs: /opt/CPInstLog/AutoUpdater.log and /opt/CPInstLog/AutoUpdateLogs/urgent_security_updates

[Expert@FWA-01:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 1/1 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 1/1 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 2/2 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:01:29 CVE-2026-85102 CVE-2026-85103
vpn1:iked* jumbofix livepatch 0/0 2026-07-15 09:13:55 sk185033
vpn1:vpnd* jumbofix livepatch 0/0 2026-07-15 09:13:55 sk185033

* reports to the management audit trail (`cplp coverage disable --patch-id <name>` to stop).
[Expert@FWA-01:0]#

CCSME, CCTE, CCME, CCVS
0 Kudos
JaAnd
Contributor

My guessing is that they would have been armed if you would install them:

a) on a SMS, as they are the ones with CPCA

b) if you have deployed SD-WAN - VPNRAD seems to be a part of this blade.

But maybe someone from CP stuff could confirm that?

I must say that this little known improvement - CP Live Patch - is a fantastic job from R&D!

0 Kudos
travelmaniac
Explorer

hm...
Manually rolling that out is nearly as much effort, as doing an HFA install..
(At least the way like that is described in that SK...)

At least an "update now"  flag in the cplp would be great.

0 Kudos
henfii
Contributor

Hello, where can I find the exact firmware for Spark? There are still unupdated FWs build on the site. 

Thank you

Aaron-pr
Participant

It looks like the Spark download page was finally updated and shows the new Build 2325 but all the download links are still pointing to the old build 998002279. Really seems like CheckPoint should have all the download links ready to go before sending you a big e-blast about a critical vulnerability. 

henfii
Contributor

Now, it shows me the new build 2325. But I see that the .imgs are swapped between 2560/2570/2580/2590 and 1600/1800/1900/2000 Appliances... I have about 50 locally managed Sparks waiting for me at our customers to update. It's going to be a long night 🙂

0 Kudos
henfii
Contributor

okay, my mistake. R82 for Spark 1500 still has the original build on the download link...

0 Kudos
Aaron-pr
Participant

Yes, 1500 was what I was attempting to download. Hopefully they fix it soon. 

0 Kudos
Aaron-pr
Participant

Looks like I found the direct link for the 1500 devices: 

https://support.checkpoint.com/results/download/145385

Oliver_Fink
Advisor
Advisor

Still no Build 4968 for R81.10.17 in sk179615. Do I have to look in a different location?

0 Kudos
Machine_Head
Advisor
Advisor

Here, this link is referenced on the CVE sk itself

https://support.checkpoint.com/results/sk/sk183153

0 Kudos
henfii
Contributor

0 Kudos
ccsjnw
Collaborator

None of the download links work:

https://support.checkpoint.com/results/sk/sk1000117/
https://support.checkpoint.com/results/sk/sk1000118/
Broken Links.png
https://support.checkpoint.com/results/download/145356

Also, if I click Check for Updates in the Gaia WebUI, it shows Jumbo Take 122 for R82 as being the latest available and Jumbo Take 40 as the latest available for R82.10.

I received the email notification from CheckPoint 48 minutes ago.

0 Kudos
_Val_
Admin
Admin

I double-checked; the download links are working.

0 Kudos
CaseyB
Advisor

The Live Patch download links work here. 

I have already applied Urgent Take 24 and it works well. Better than the jumbo approach for sure. 

ccsjnw
Collaborator

CaseyB, that page is blank when I open (and fresh it) from the UK...

0 Kudos
CaseyB
Advisor

0 Kudos
ccsjnw
Collaborator

Still not working here:

Broken Links3.png
See the above screenshot...
Are you positive that these links have been made available to customers, and not just internally?

0 Kudos
CaseyB
Advisor

That's what I used as a customer. ¯\_(ツ)_/¯

0 Kudos
ccsjnw
Collaborator


The WebUI in Gaia is now showing the full update packages for both R82 and R82.10, so I'm using that method...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events